What does AUSTRAC actually do?
AUSTRAC is the Australian Transaction Reports and Analysis Centre. It describes its own function as a dual role, acting as both a regulator and a financial intelligence unit to keep Australia safe. That dual role lets it use financial intelligence and regulation together to detect, deter and disrupt money laundering, terrorism financing, proliferation financing, and serious and organised crime. See About AUSTRAC.
On the regulatory side, AUSTRAC supervises reporting entities to make sure they comply with their obligations to have systems and controls in place that manage their risks and protect them and the community from financial crime. The governing statute is the Anti-Money Laundering and Counter-Terrorism Financing Act 2006.
On the intelligence side, AUSTRAC collects and analyses financial reports and information from reporting entities and other data sources, creating targeted, actionable intelligence for law enforcement and national security investigations. Its intelligence functions sit within the national intelligence community as defined under section 4 of the Office of National Intelligence Act 2018.
Its stated vision is a community protected from financially enabled crime.
Who does AUSTRAC regulate?
AUSTRAC names the industries it regulates as accountants, banks, casinos, conveyancers, dealers in precious stones, metals and products, financial service providers, legal professionals, pubs, clubs and bookmakers, real estate, remittance service providers, superannuation providers and virtual asset service providers. See regulating businesses.
That list is much longer than it was a year ago. The Tranche 2 reforms brought lawyers, conveyancers, accountants, trust and company service providers, real estate professionals and dealers in precious stones and metals into the regime from 1 July 2026. AUSTRAC stated in March 2026 that on that date the number of businesses it regulates would grow from around 19,000 to close to 100,000 nationwide, describing the change as the most significant overhaul of Australia's AML/CTF framework in more than 20 years.
The obligations that follow are consistent across sectors. Reporting entities must implement AML/CTF controls and report financial transactions and suspicious activity. In practice that means enrolling with AUSTRAC, maintaining an AML/CTF program, conducting customer due diligence including ongoing due diligence, submitting suspicious matter reports, threshold transaction reports and international funds transfer reports where they apply, and keeping records.
AUSTRAC supports and checks compliance through activities including identifying new and emerging risks, collecting data for regulatory insights, assessing industry vulnerabilities and threats to Australia's financial sector, working with industry to improve risk management, educating industry on risks and compliance, and supporting national security and law enforcement operations.
Where does AI fit in AUSTRAC's work?
AUSTRAC has published an AI transparency statement, and the position it sets out is a useful benchmark for regulated firms. AUSTRAC has not yet deployed AI which directly interacts with the public or is involved in decision making and administrative action without human intervention. It is currently trialling enterprise generative AI systems to explore the benefits and risks responsibly, including internal tools for workplace productivity and tools to support service delivery, with clear human oversight.
The controls are specific. AUSTRAC makes limited use of public generative AI tools for workplace productivity, in alignment with Digital Transformation Agency staff guidance, and applies mandatory protective security controls so that no sensitive or classified information is entered into public generative AI systems. For its definition of an AI system it defers to the Digital Transformation Agency, which describes a machine-based system that infers from its input how to generate outputs such as predictions, content, recommendations or decisions, with varying levels of autonomy and adaptiveness after deployment.
One nuance is worth knowing. Because AUSTRAC's intelligence functions form part of the national intelligence community, the responsible use of AI in government policy specifically exempts those functions from compliance with the policy, including the transparency statement. AUSTRAC says it may voluntarily adopt elements of the policy for its intelligence functions where it can do so without compromising national security.
What should practitioners do about AUSTRAC obligations?
Confirm whether you provide a designated service before anything else. Regulation follows the service, not the job title, so the question is what you do for customers rather than what industry you sit in.
If you use AI in transaction monitoring, customer screening or suspicious matter triage, treat it as a control that has to be documented, tested and explained. The obligation to have systems and controls is yours. Outsourcing the work to a vendor or a model does not move the obligation, and an AML/CTF program that cannot describe how an automated alert was generated is difficult to defend in a supervisory review.
Match the regulator's own data discipline. AUSTRAC keeps sensitive and classified information out of public generative AI tools entirely. Customer identity documents, source of wealth material and suspicious matter content deserve the same treatment, particularly given the tipping off offence.
Finally, read AUSTRAC guidance for what it is. AUSTRAC states plainly that its guidance sets out how it interprets the legislation, that Australian courts are ultimately responsible for interpreting these laws, and that the guidance is not a substitute for legal advice.
Bottom line
AUSTRAC carries two jobs at once, supervising reporting entities under the anti-money laundering and counter-terrorism financing regime and acting as Australia's financial intelligence unit. Whether it regulates a business turns on the designated service provided rather than the industry label, and the obligations that follow are consistent: enrol, maintain an AML/CTF program, conduct customer due diligence, submit the required reports and keep records. Where AI touches transaction monitoring, customer screening or suspicious matter triage, treat it as a control to be documented, tested and explained, because outsourcing the work to a vendor or a model does not move the obligation. The regulator's own posture, human decision makers plus a hard rule against sensitive material entering public generative AI tools, is a fair benchmark for a regulated firm to hold itself to.
TheAICommand. Intelligence, At Your Command.*
TheAICommand. Intelligence, At Your Command.
